Password Strength: An Empirical Analysis

被引:0
|
作者
Dell'Amico, Matteo [1 ]
Michiardi, Pietro [1 ]
Roudier, Yves [1 ]
机构
[1] Eurecom, Sophia Antipolis, France
关键词
SECURITY;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
It is a well known fact that user-chosen passwords are somewhat predictable: by using tools such as dictionaries or probabilistic models, attackers and password recovery tools can drastically reduce the number of attempts needed to guess a password. Quite surprisingly, however, existing literature does not provide a satisfying answer to the following question: given a number of guesses, what is the probability that a state-of-the-art attacker will be able to break a password? To answer the former question, we compare and evaluate the effectiveness of currently known attacks using various datasets of known passwords. We find that a "diminishing returns" principle applies: in the absence of an enforced password strength policy, weak passwords are common; on the other hand, as the attack goes on, the probability that a guess will succeed decreases by orders of magnitude. Even extremely powerful attackers won't be able to guess a substantial percentage of the passwords. The result of this work will help in evaluating the security of authentication means based on user-chosen passwords, and our methodology for estimating password strength can be used as a basis for creating more effective proactive password checkers for users and security auditing tools for administrators.
引用
收藏
页数:9
相关论文
共 50 条
  • [21] An Empirical Study of Picture Password Composition on Smartwatches
    Belk, Marios
    Fidas, Christos
    Katsi, Eleni
    Constantinides, Argyris
    Pitsillides, Andreas
    HUMAN-COMPUTER INTERACTION, INTERACT 2021, PT IV, 2021, 12935 : 655 - 664
  • [22] An Analysis of Password Managers' Password Checkup Tools
    Hutchinson, Adryana
    Munyendo, Collins W.
    Aviv, Adam J.
    Mayer, Peter
    EXTENDED ABSTRACTS OF THE 2024 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2024, 2024,
  • [23] Think Harder! Investigating the Effect of Password Strength on Cognitive Load during Password Creation
    Abdrabou, Yasmeen
    Abdelrahman, Yomna
    Khamis, Mohamed
    Alt, Florian
    EXTENDED ABSTRACTS OF THE 2021 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS (CHI'21), 2021,
  • [24] Influences of Human Cognition and Visual Behavior on Password Strength during Picture Password Composition
    Katsini, Christina
    Fidas, Christos
    Raptis, George E.
    Belk, Marios
    Samaras, George
    Avouris, Nikolaos
    PROCEEDINGS OF THE 2018 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS (CHI 2018), 2018,
  • [25] A probabilistic Framework for Improved Password Strength Metrics
    Galbally, Javier
    Coisel, Iwen
    Sanchez, Ignacio
    2014 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2014,
  • [26] Password Security: Password Behavior Analysis at a Small University
    Awad, Mohammed
    Al-Qudah, Zakaria
    Idwan, Sahar
    Jallad, Abdul Halim
    2016 5TH INTERNATIONAL CONFERENCE ON ELECTRONIC DEVICES, SYSTEMS AND APPLICATIONS (ICEDSA), 2016,
  • [27] PESrank: An Explainable online password strength estimator
    David, Liron
    Wool, Avishai
    JOURNAL OF COMPUTER SECURITY, 2022, 30 (06) : 877 - 901
  • [28] PassMon: A Technique for Password Generation and Strength Estimation
    Murmu, Sanjay
    Kasyap, Harsh
    Tripathy, Somanath
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2022, 30 (01)
  • [29] PassMon: A Technique for Password Generation and Strength Estimation
    Sanjay Murmu
    Harsh Kasyap
    Somanath Tripathy
    Journal of Network and Systems Management, 2022, 30
  • [30] Improving multiple-password recall: an empirical study
    Zhang, Jie
    Luo, Xin
    Akkaladevi, Somasheker
    Ziegelmayer, Jennifer
    EUROPEAN JOURNAL OF INFORMATION SYSTEMS, 2009, 18 (02) : 165 - 176